Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Join the FabCon + SQLCon recap series. Up next: Power BI, Real-Time Intelligence, IQ and AI, and Data Factory take center stage. All sessions are available on-demand after the live show. Register now

Reply
pragyamishra
Helper II
Helper II

how to implement RLS in SSAS

Hi All,

 

Can someone please tell me if I can implement Dynamic Row level Security in SSAS if my users have not joined a domain and my report server is also not on any domain?

 

Thanks,

Pragya Mishra

1 ACCEPTED SOLUTION

Hi @muchinski

 

Got this reply in a SSAS forum.

 

If you are not on a domain you will have to create local users on the server machine that is running SSAS with the identical username and password that your users use to logon to their client machines. Then you can put those local accounts from the server into roles in SSAS. When you are on a workgroup the user tokens get created by securely hashing the username and password so as long as these are identical the workgroup will map the client accounts to the server account. This also means that any time a user changes their local password you will also need to change the password for the account on the SSAS server.

 

So, I believe I should be able to do it. I shall test it soon enough. 🙂

View solution in original post

2 REPLIES 2
muchinski
Resolver II
Resolver II

Hi, no, you can't.

For Row Level Security, you rely on Windows Authentication. This is what allow you to use the USERNAME() function to dinamically filter the data on Roles.

Hi @muchinski

 

Got this reply in a SSAS forum.

 

If you are not on a domain you will have to create local users on the server machine that is running SSAS with the identical username and password that your users use to logon to their client machines. Then you can put those local accounts from the server into roles in SSAS. When you are on a workgroup the user tokens get created by securely hashing the username and password so as long as these are identical the workgroup will map the client accounts to the server account. This also means that any time a user changes their local password you will also need to change the password for the account on the SSAS server.

 

So, I believe I should be able to do it. I shall test it soon enough. 🙂

Helpful resources

Announcements
April Power BI Update Carousel

Power BI Monthly Update - April 2026

Check out the April 2026 Power BI update to learn about new features.

New to Fabric survey Carousel

New to Fabric Survey

If you have recently started exploring Fabric, we'd love to hear how it's going. Your feedback can help with product improvements.

Power BI DataViz World Championships carousel

Power BI DataViz World Championships - June 2026

A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.

FabCon and SQLCon Highlights Carousel

FabCon &SQLCon Highlights

Experience the highlights from FabCon & SQLCon, available live and on-demand starting April 14th.